Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.
History

Thu, 27 Mar 2025 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CPEs cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Thu, 27 Mar 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Mintplexlabs
Mintplexlabs anythingllm
CPEs cpe:2.3:a:mintplexlabs:anythingllm:-:*:*:*:*:*:*:*
Vendors & Products Mintplexlabs
Mintplexlabs anythingllm
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-03-27T10:44:21.811Z

Reserved: 2024-01-19T20:41:43.121Z

Link: CVE-2024-0763

cve-icon Vulnrichment

Updated: 2024-08-01T18:18:18.272Z

cve-icon NVD

Status : Modified

Published: 2024-02-27T22:15:14.597

Modified: 2025-03-27T11:15:36.570

Link: CVE-2024-0763

cve-icon Redhat

No data.